Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,169 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,957
Categories
17,726
9,432
3,736
3,663
3,653
Platforms
39,169
6,860
6,378
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
Detects file creation, modification, or renaming in System32 by TieringEngineService.exe or MsMpEng.exe within a short time frame.
Detects suspicious service creation or registry modifications involving WpnUserHost that do not reference System32.
Detects suspicious service creation or registry modifications involving WpnUserHost that do not reference System32.
Detects suspicious service creation or registry modifications involving WpnUserHost that do not reference System32.
Detects suspicious service creation or registry modifications related to wscl.exe that mimic persistence mechanisms.
Detects suspicious service creation or registry modifications related to wscl.exe that mimic persistence mechanisms.
Detects remote service creation consistent with PsExec-style lateral movement by correlating network logons (Type 3) with subsequent service installations.
Detects persistence activities initiated by Postgres-related processes or users involving scheduled tasks and system services.
Detects persistence activities initiated by Postgres-related processes or users involving scheduled tasks and system services.
Detects persistence activities initiated by Postgres-related processes or users involving scheduled tasks and system services.
Detects NTLM network logons (NtLmSsp) for accounts that may have been targets of certificate-based identity abuse (e.g., ESC1). Attackers often leverage this technique to extract NTLM hashes from PKINIT TGT PACs and subsequently utilize Pass-the-Hash for lateral movement within the network.
Detects suspicious DNS queries to external service interaction domains often used for out-of-band interactions after successful RCE
This is something I have seen many times during my years working in cybersecurity: users download software with a filename they recognize and trust, but the file behind that name can be something completely different.
Monitoring the filename is not enough. Monitoring the hash is better, but legitimate software changes constantly: new version, new SHA256, another hash to validate and maintain. So I started thinking about how AI agents could help us here — not by deciding what is malicious, but by doing the repetitive work for us.
For this research, I built an AI-maintained baseline of legitimate software and used it from KQL to hunt two different scenarios:
🎯 Known filename + Unknown hash + Untrusted download source
Monitoring the filename is not enough. Monitoring the hash is better, but legitimate software changes constantly: new version, new SHA256, another hash to validate and maintain. So I started thinking about how AI agents could help us here — not by deciding what is malicious, but by doing the repetitive work for us.
For this research, I built an AI-maintained baseline of legitimate software and used it from KQL to hunt two different scenarios:
🎯 Known filename + Unknown hash + Untrusted download source
Detects Adblock.dll used by Docro Hijacker to bypass Chrome Secure Preferences HMAC-SHA256 integrity checks and register infected browser UUID via vendralo[.]info
This rule detects the use of PowerShell to modify Microsoft Defender settings to disable real-time, behavior, and IOAV protection, while simultaneously adding a full-drive exclusion for the root directory (C:\). This behavior is characteristic of an adversary attempting to disable security monitoring to facilitate further malicious activity or avoid detection.
Detects suspicious persistence mechanisms initiated by the 'wscl.exe' executable. The rule monitors for registry run key modifications, service installation via command-line arguments, and service creation events, specifically filtering for non-standard execution paths (outside of System32, SysWOW64, or Program Files).
Detects suspicious persistence mechanisms initiated by the 'wscl.exe' executable. The rule monitors for registry run key modifications, service installation via command-line arguments, and service creation events, specifically filtering for non-standard execution paths (outside of System32, SysWOW64, or Program Files).
Detects HVNC backdoor payload containing hardcoded AV/EDR process names combined with process enumeration APIs and a hex-suffixed mutex naming pattern, reducing false positives from generic AV name or API string matches alone
Detects HVNC backdoor payload containing hardcoded AV/EDR process names combined with process enumeration APIs and a hex-suffixed mutex naming pattern, reducing false positives from generic AV name or API string matches alone
Detects NSIS installer/archive contents bundling the specific unsigned/renamed UpdateAssistant.exe (aka AppUpdateHelper.exe) payload alongside its associated staged runtime DLLs and known malicious file paths/hashes used as cover noise for DLL sideloading staging
Detects NSIS installer/archive contents bundling the specific unsigned/renamed UpdateAssistant.exe (aka AppUpdateHelper.exe) payload alongside its associated staged runtime DLLs and known malicious file paths/hashes used as cover noise for DLL sideloading staging
Page 416 of 1866



